← Vulnerability feed

Vulnerability record · CVE-2022-25075 · published 24 February 2022

CVE-2022-25075: TOTOLink A3000RU router command injection via QUERY_STRING

TTotolink · A3000ru Firmware

TOTOLink A3000RU firmware V5.9c.2280_B20180512 contains an OS command injection flaw in the "Main" function, reachable through the QUERY_STRING parameter. Successful exploitation lets an attacker run arbitrary commands on the device, which is severe for an internet-facing router. The record does not state which firmware builds are fixed beyond the referenced patch link.

9.8 CVSS 3.1 Critical EPSS 56% · top 1.0% CWE-78 · OS command injection
9.8CVSS 3.1 base score, v2 7.5
56%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

TOTOLink A3000RU V5.9c.2280_B20180512 was discovered to contain a command injection vulnerability in the "Main" function. This vulnerability allows attackers to execute arbitrary commands via the QUERY_STRING parameter.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.8 with network reachability, no authentication and no user interaction, plus public exploit code and a very high EPSS score, make this an urgent fix for any exposed A3000RU.

What it is

TOTOLink A3000RU firmware V5.9c.2280_B20180512 contains an OS command injection flaw in the "Main" function, reachable through the QUERY_STRING parameter. Successful exploitation lets an attacker run arbitrary commands on the device, which is severe for an internet-facing router. The record does not state which firmware builds are fixed beyond the referenced patch link.

Impact

An attacker gains arbitrary command execution on the router, allowing full compromise of the device, its configuration and any traffic or credentials it handles. Given the network vector and no required privileges, this can be leveraged for lateral movement into the network it serves.

Attack surface

The flaw is reached over the network via the QUERY_STRING parameter (CVSS AV:N, PR:N, UI:N), so no authentication or user interaction is needed. Any exposed management or web interface on the affected firmware is a potential entry point.

Exploitation

CISA KEV does not list this CVE, but EPSS is high at roughly 0.56 (99th percentile) and the reference is tagged Exploit, indicating public exploit code exists. No ransomware association is documented.

What to do

  • Apply the vendor patch or upgrade to a fixed firmware build; the reference is tagged Patch, so check TOTOLink's advisory for the corrected version.
  • If no patch is available, remove the device's management interface from the internet and restrict access to a trusted management VLAN or allowlisted hosts.
  • Disable remote administration and any unused WAN-facing services on the router.
  • Replace end-of-life firmware with a supported device if the vendor no longer issues updates.
  • Monitor the device for unexpected outbound connections or command execution artifacts until patched.

Detection

  • Inspect web server and router logs for requests with suspicious characters or shell metacharacters in the QUERY_STRING parameter.
  • Alert on unexpected processes or outbound connections originating from the router's management interface.
  • Watch for repeated or malformed requests to the affected endpoint from external or untrusted source IPs.
  • Compare running firmware version against the vendor's fixed release to identify unpatched devices.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-25075 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-28035Totolink a830r firmware os command injection vulnerabilityTOTOLINK A830R V4.1.2cu.5182_B20201102 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through th…EPSS 1.3%9.8CVE-2025-28036Totolink a950rg firmware os command injection vulnerabilityTOTOLINK A950RG V4.1.2cu.5161_B20200903 was found to contain a pre-auth remote command execution vulnerability in the setNoticeCfg function through t…EPSS 1.3%9.8CVE-2025-28034Totolink a800r firmware os command injection vulnerabilityTOTOLINK A800R V4.1.2cu.5137_B20200730, A810R V4.1.2cu.5182_B20201026, A830R V4.1.2cu.5182_B20201102, A950RG V4.1.2cu.5161_B20200903, A3000RU V5.9c.5…EPSS 1.3%9.8CVE-2022-26206Totolink a830r firmware os command injection vulnerabilityTotolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…EPSS 2.2%9.8CVE-2022-26207Totolink a830r firmware os command injection vulnerabilityTotolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…EPSS 2.2%9.8CVE-2022-26208Totolink a830r firmware os command injection vulnerabilityTotolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…EPSS 2.8%9.8CVE-2022-26209Totolink a830r firmware os command injection vulnerabilityTotolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…EPSS 2.2%9.8CVE-2022-26210Totolink a830r firmware os command injection vulnerabilityTotolink A830R V5.9c.4729_B20191112, A3100R V4.1.2cu.5050_B20200504, A950RG V4.1.2cu.5161_B20200903, A800R V4.1.2cu.5137_B20200730, A3000RU V5.9c.518…EPSS 5.7%

Source: NIST National Vulnerability Database (record CVE-2022-25075), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.